Latvia's Road Traffic Safety Directorate, known as CSDD, has confirmed a major data breach affecting over 1.2 million individuals and 200,000 businesses. The breach exposed sensitive information like personal identification numbers, vehicle registration details, and payment records dating back to 2008. The agency, under Latvia's Transport Ministry, affirmed that no phone numbers, email addresses, usernames, or passwords were compromised. Following the incident, Latvia's CERT warned that the leaked data could be used for social engineering and fraud. In response, CSDD has temporarily restricted access to certain vehicle information services and is working with cybersecurity authorities to identify the attackers. The breach, described as 'complex', exploited a vulnerability in CSDD's system, with several cybersecurity requirements reportedly unmet. Political fallout has been significant, leading to the resignation of CSDD's supervisory board and calls for further resignations from agency leadership, including its chief, Aivars Aksenoks, who stated he would step down after aiding in the investigation. The Latvian telecom company Tet, responsible for some of CSDD's IT infrastructure, has denied responsibility pending further investigation. This breach follows a recent cyberattack on another Latvian state-owned company, intensifying concerns over national cybersecurity measures.
Latvian Data Breach Exposes Over a Million Citizens' Information
Latvian road traffic agency breach exposed vehicle data affecting ~two-thirds of population, prompting official resignations.


